Most ChatGPT Extensions Are Just Malware

  Рет қаралды 81,784

John Hammond

John Hammond

Күн бұрын

j-h.io/guardio || Guardio protects you from malicious browser extensions and scams like these! Get 20% off with my link: j-h.io/guardio
Guardio's "FakeGPT" writeup: labs.guard.io/fakegpt-new-var...
00:00 Fake Chat GPT
01:53 Shopping Spree Begin!
03:52 How could threat actors use ChatGPT?
06:48 Shopping Spree return
08:08 Guardio Research
10:15 Sample code
11:21 Taking over FB accounts
14:00 Final Thoughts
🔥 KZfaq ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 155
@BeavisOfArabia
@BeavisOfArabia Жыл бұрын
Heh, reminds me of when everyone would install browser extensions that are malicious back around the mid 2000's.
@kaas12
@kaas12 Жыл бұрын
People often didn’t even know they installed them and they just appeared
@jjann54321
@jjann54321 Жыл бұрын
They still do. The definition of "malicious" has changed. Capturing/accessing all user data was malicious, now it's an "I agree" checkbox in the User Agreement.
@toniok.4726
@toniok.4726 Жыл бұрын
@@kaas12 they all come from 'other' installer or even just random click on a website.
@cat-le1hf
@cat-le1hf Жыл бұрын
people still do
@exmerion
@exmerion Жыл бұрын
Toolbars
@bitelaserkhalif
@bitelaserkhalif Жыл бұрын
One drawback of ChatGPT IMO is reliance on the central party (Open AI), no self hosted alternative.
@ColinTimmins
@ColinTimmins Жыл бұрын
You can run light weight models that can do extremely well.
@XaneMyers
@XaneMyers Жыл бұрын
Another drawback is just how many things that ChatGPT knows but refuses to let you ask it about. (I know there are jailbreaks like DAN but while I bet 99% of people would disagree, I think that that functionality should just be there without any workarounds, especially from the ironically-named *OPEN* AI.)
@tinystego1836
@tinystego1836 Жыл бұрын
Even if you can self host, you're still relying on OpenAI's algorithms.
@parabolicpanorama
@parabolicpanorama Жыл бұрын
@@tinystego1836 what algorithms? they are models.
@SameLif3
@SameLif3 Жыл бұрын
We need open sources
@hydroponicgard
@hydroponicgard Жыл бұрын
How to exit vim got me laughing. Classic question to ask CGPT!
@cybersechs1368
@cybersechs1368 Жыл бұрын
NANO >> VIM
@StankyLegss
@StankyLegss Жыл бұрын
@@cybersechs1368 subl >>>>>>>
@pabloqp7929
@pabloqp7929 Жыл бұрын
"How to exit vim" has nearly 3M visits at Stackoverflow 🙈
@niskita
@niskita Жыл бұрын
When taking a test and you got test anxiety, that question makes sense
@MrMetallicabk
@MrMetallicabk Жыл бұрын
We blocked chatgpt at work because of data and privacy concerns. I'm using it at home to study Azure / M365 tools and features but I'd never use an app or a browser extension because of those risks you described and the overly permissive access they have. It's both interesting and scary at the same time.
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
O.o Yeah, I've manipulated ChatGPT4 to make me RAT malware script, SSH requester, and some other stuff I've done on my own and have followed of ethical hackers' instructions here on KZfaq on multiple occasions. It's a super useful tool for finding out information on ethical hacking for the good (and the bad), amongst much other help on stuff, with some error here and there. 🤓😅🔥💻👨‍💻🔥👌👌🤝🤝🤝🔥🔥🔥🤑🤑😎😎
@m3i3r
@m3i3r Жыл бұрын
Bro youre using stuff from ms
@KevinCrouch0
@KevinCrouch0 Жыл бұрын
Ugh now I'm just thinking about Joe user. Just pacing in who knows what kind of potentially sensitive data into chatGPT
@therealb888
@therealb888 Жыл бұрын
Finally people are talking about privacy. Apart from Italy, Russia & China banning people are completely oblivious to the privacy angle. Everything you type into chatgpt is recorded & used for training future models & fine tuning current ones.
@therealb888
@therealb888 Жыл бұрын
​@@m3i3r What's your point? Azure & M365 are the best at their field. You can't grow without learning the best.
@stevecruztube
@stevecruztube Жыл бұрын
(6:06) He said he didn't know what "other cyber criminals" were doing with AI stuff.
@TheTocoe
@TheTocoe Жыл бұрын
Freudian slip? 🤔
@joaquinejberowicz3947
@joaquinejberowicz3947 Жыл бұрын
hahahahahahaah
@therealb888
@therealb888 Жыл бұрын
​@@TheTocoe 😂 confirmed.
@bustaphatty
@bustaphatty Жыл бұрын
Wow, this video is really eye-opening! It's a good reminder that we need to be extra careful when downloading and using extensions. Thanks for the info!
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
:p Yeah, I've manipulated ChatGPT4 to make me RAT malware script, SSH requester, and some other stuff I've done on my own and have followed of ethical hackers' instructions here on KZfaq on multiple occasions. It's a super useful tool for finding out information on ethical hacking for the good (and the bad), amongst much other help on stuff, with some error here and there. 🤓😅🔥💻👨‍💻🔥👌👌🤝🤝🤝🔥🔥🔥🤑🤑😎😎
@mihalachebogdan1
@mihalachebogdan1 Жыл бұрын
Much love to you JH ! Thx for the video
@rebootfactory
@rebootfactory Жыл бұрын
Hey John, thanks for the great video. I love that you touched on using GPT for nefarious purposes. It's an interesting question and definitely wide open in terms of the ethical debate. The jury is certainly out on that. To your point it really depends a lot on the underlying skills of the user and what they are trying to use the tool to do imo. Building in guard rails for that seems difficult if not completely impossible from my personal lay person point of view. As far as the question of browser extensions I completely agree on the attack surface bit. I generally avoid any sort of browser extensions, or anything else, unless I can verify 100% the program is explicitly doing what it's meant to do. It's wild to me that there are so many things in the play store that clearly violate that concept and go beyond executing on the stated purpose of the app. or whatever else it is. I think it's a great thing for you to be brining attention to this and hopefully it helps with general awareness in terms of keeping people safe. Thanks for what you do and keep up the great work! Huge fan of your content and appreciate all you sharing your expert opinions!
@MiteBlueRuby
@MiteBlueRuby Жыл бұрын
if chatgpt was made in the IE age we would have chatgpt toolbars too 💀
@toniok.4726
@toniok.4726 Жыл бұрын
wrong era could end yoir company. so impossible.
@cryptoafc7655
@cryptoafc7655 Жыл бұрын
John you content is amazing & educating
@CrittingOut
@CrittingOut Жыл бұрын
"Wait, it's all just malware?" "Always has been"
@RAIN_B0T
@RAIN_B0T Жыл бұрын
always check things first, sometimes even a quick google query about something can bring you more infos if you dont have the capability or understanding to check the code yourself
@iusegentoobtw
@iusegentoobtw Жыл бұрын
"Nothing is sophisticated" I like that quote a lot.
@KwincksIT
@KwincksIT Жыл бұрын
Google dissing the competetors Chatbot AI... nothing new there.. i bet Google's IA wont have anything bad said about it...
@238SAMIxD
@238SAMIxD Жыл бұрын
Advertising a browser extension in the video about malicious extensions. Seems legit
@tonysolar284
@tonysolar284 Жыл бұрын
This is why I use the API directly
@jawyromero3951
@jawyromero3951 Жыл бұрын
Well, what do you think of copilot, it can be the great panacea of computer security in terms of defense?
@netoeli
@netoeli Жыл бұрын
this just elaborates how horrendously bad the extension stores for chrome and firefox are full of data exfiltration apps or malware
@guilherme5094
@guilherme5094 Жыл бұрын
And thanks again John.
@TequilaDave
@TequilaDave Жыл бұрын
I have a Faceache account but haven't logged into it for over 5 years apart to enable MFA, I also block Facebook on my home network with PiHole. Would I still be suseptical to this attack if I decided to install an extension? (not that I often do)
@rasydev
@rasydev Жыл бұрын
Thank info ❤
@REDSIDEofficial
@REDSIDEofficial 10 ай бұрын
Is there any chance in this way they can hack anydesk or teamviewer, and getting data from your hard drivers ? this happened to my friend, and i saw a process which was active and it was located in the anydesk folder data, when i stop the process it shows again, even when i uninstalled the anydesk, is this possible ? also this happened even when i cleaned his pc with antivirus !
@pizzabossxd
@pizzabossxd Жыл бұрын
nice vid John
@d3layd
@d3layd Жыл бұрын
Been saying this since November. Same with mobile apps
@jjann54321
@jjann54321 Жыл бұрын
IMO the average user/consumer could not care less. They want to see and or be seen 24/7, unlimited data/coverage/battery and to never have to remember passwords. And don't forget, pretty packaging.
@fss1704
@fss1704 Жыл бұрын
The average consumer is pretty dumb. No shit idiocracy has become a documentary
@chrismagistrado6014
@chrismagistrado6014 Жыл бұрын
I think using ChatGPT or an AI along with a front-end will create million dollar companies overnight. Dropbox is just a front-end for AWS's S3. Even though users can setup an S3 bucket on their own, companies like Dropbox make it easier to new users of technology to enter.
@amogus-dn8qn
@amogus-dn8qn 11 ай бұрын
if you're suspicious about learn basic web programming lingo from chatgpt then ask chatgpt to do the grunt work of making a web extension of your choice for you using some of the lingo you learned
@ianmcpherson2301
@ianmcpherson2301 Жыл бұрын
Depends on who writes the definition of malware. Some say Windows, Linux, or any other OS varient is malware. It all comes down to risk assesment imho and ChatGPT is really up there in the malware stakes because of who is owns ChatGPT and why it is being pushed so hard by so many 'developers' on various platforms. Just waiting for its use to be mandated.
@Lodinn
@Lodinn Жыл бұрын
"I don't know what *other* cybercriminals are doing" - I see what you did there John >_>
@000t9
@000t9 Жыл бұрын
There will be always pros and cons - including ChatGPT; we will see different issues with that AI…
@aykutcan_
@aykutcan_ Жыл бұрын
project exiting vim. need asap.
@disdroid
@disdroid Жыл бұрын
:!rm -rf /
@theunium
@theunium Жыл бұрын
press your computer's power button, works for me.
@Dr.Malware
@Dr.Malware Жыл бұрын
Do a video on Bing AI also
@guycohen4403
@guycohen4403 Жыл бұрын
1:07 lmao how to exit vim😂. This joke never gets old
@AngryWoodenFork
@AngryWoodenFork Жыл бұрын
I checked out the extensions a while back. Didn't install anyone because what's the point haha. Also, the permissions they require are insane.
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
^_^ Yeah, I've manipulated ChatGPT4 to make me RAT malware script, SSH requester, and some other stuff I've done on my own and have followed of ethical hackers' instructions here on KZfaq on multiple occasions. It's a super useful tool for finding out information on ethical hacking for the good (and the bad), amongst much other help on stuff, with some error here and there. 🤓😅🔥💻👨‍💻🔥👌👌🤝🤝🤝🔥🔥🔥🤑🤑😎😎
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
Nice PFP for John Doe, bro/sis! Haha xD 😎
@sweepingtime
@sweepingtime Жыл бұрын
lol can't let a good opportunity for mischief ever go to waste
@mikerope5785
@mikerope5785 Жыл бұрын
It's always a red flag to change your passwords when you see someone with a defcon t-shirt on 😏
@evazq4317
@evazq4317 Жыл бұрын
So what is the real official way link/website to get Chat GPT?
@robertgajda5365
@robertgajda5365 Жыл бұрын
" ... other cyber criminals ... " LMAO. Freudian slip, @John Hammond?
@__ZANE__
@__ZANE__ Жыл бұрын
easy solution. don't use fakebook
@lennartandersen7485
@lennartandersen7485 Жыл бұрын
All chatGPT is doing is make people dumber, just my two cents.......
@zaccampa4055
@zaccampa4055 11 ай бұрын
Exactly. Having something do the work for you will only get you so far.
@WatchDragon
@WatchDragon Жыл бұрын
Its better than searching google because it docent dick wave about how good they are at coding
@digimbyte
@digimbyte Жыл бұрын
why aren't session tokens more secure?
@jdclineful
@jdclineful Жыл бұрын
We need ChatGPT Bonzai Buddy and we will have come full circle.
@real-ludovico
@real-ludovico Жыл бұрын
I love how the subtitles say "Chad GPT" at the start
@DaRealTriTi
@DaRealTriTi Жыл бұрын
Also most chat gpt apps on the app store
@Dakktyrel
@Dakktyrel Жыл бұрын
In life, the process of gaining intelligence mostly comes with a level of wisdom on how to use the knowledge gained, for good or bad. Having 'artificial intelligence' skips the process of learning and gaining wisdom. Intelligence without wisdom is one of the the single greatest threats to humanity.
@parabolicpanorama
@parabolicpanorama Жыл бұрын
GPT is also confidently wrong around 1/10 times for text inputs which is insane seeing how people are using it blindly for work.
@IntiArtDesigns
@IntiArtDesigns Жыл бұрын
ChatGPT is definitely NOT going to write malware for you, or even give you any juicy red-teaming information, not since it got nerfed due to safety concerns. Unless you have a really good 0-day unpatched jailbreak prompt that can bypass all the filters.
@hostjhall
@hostjhall Жыл бұрын
If you are running a 3rd party app that uses openai api for chatbotting, wouldn't there be ethical concerns about having your app collect so much data? Especially passwords, cookies, active sessions, etc? I'm working on my own 3rd party chatgpt python program and I questioned if I should make the file save a LOCAL log of the users conversation, which I needed for aspects of the program itself to reference, but even then I was concerned about how an end user would feel about the creation of a text log that I would never see as the developer..... I cant wrap my head around the kind of oversight that would allow someone to collect data like that while maintaining simple ethical standards o.o
@Tabu11211
@Tabu11211 Жыл бұрын
How do you get extensions though?!
@notadev9000
@notadev9000 Жыл бұрын
Don't think this is the video for that
@barrianic4
@barrianic4 Жыл бұрын
read the reviews
@Dahlah.FightMe
@Dahlah.FightMe Жыл бұрын
Nice :D
@RPBCACUEAIIBH
@RPBCACUEAIIBH Жыл бұрын
I'm using ChatGPT because whoever doesn't will soon not be able to keep up. ...but do I trust it? NO! ;) (That is why I'm also using Open Assistant... It's not as good, still under development but I really don't want to rely on 1 service...)
@adammiller9114
@adammiller9114 Жыл бұрын
This sounds like a lot of work but you could try building your own.
@mrityunjayadixit1821
@mrityunjayadixit1821 Жыл бұрын
I don't understand how can we be so stupid! To create AI systems when we don't have any backup for AI backfiring!
@workflowinmind
@workflowinmind Жыл бұрын
Crazy that no one realise this is Seth Rogen disguised as a geek
@MFoster392
@MFoster392 Жыл бұрын
I think you have to know how to write malware to have any luck at tricking ChatGBT into writing it, i don't think a "Newbie" script kitty could do it . I actually tried to use a Edge extension that was flagged by my Bitdefender security yesterday
@nordgaren2358
@nordgaren2358 Жыл бұрын
It only took me four questions to get chat got to give the recursive encrypt file routine you see in the video. Two of you don't count the first one it rejected and me asking it to change libraries. The part you need some experience in is cleaning up the code. I was still kinda impressed at what it did give me, though!
@blikjecola9172
@blikjecola9172 Жыл бұрын
Ai boy
@chriscard6544
@chriscard6544 Жыл бұрын
lolll facebook creds, there are still people on facebook (another malware, my opinion) ?
@joshuawinters-brown4831
@joshuawinters-brown4831 Жыл бұрын
Talk about malicious extensions, and then show me a “good” extension to install. Just like every other extension here, what does guardio collect and sell? 😹😹😹
@faker-scambait
@faker-scambait Жыл бұрын
👍👍👍👍
@lw4311
@lw4311 Жыл бұрын
I thought I entered right wing youtube because of the thumbnail, but no, it's just John Hammond
@AmCanTech
@AmCanTech Жыл бұрын
These aren't gpt built in extensions
@noahh1552
@noahh1552 Жыл бұрын
AIRPRM is legitimate imo
@kosmonautofficial296
@kosmonautofficial296 Жыл бұрын
I knew this wasn’t a crowder video because his videos are never recommended.
@andreaskrbyravn855
@andreaskrbyravn855 Жыл бұрын
Ai in everything people want to do as little as possible
@Synclon
@Synclon Жыл бұрын
ChatGPT+Kali Linux= ?
@tablettablete186
@tablettablete186 Жыл бұрын
Are extensions malware? *Always has been!* 🔫
@Disatiere
@Disatiere Жыл бұрын
"How to get chatgpt on your phone" lesser knowledgable users that dont understand what a web browser is
@mishal_legit
@mishal_legit Жыл бұрын
Sound out of sync ? or just me ?
@nordgaren2358
@nordgaren2358 Жыл бұрын
Yea, idk why, but the last 1/3 of the video got out of sync.
@jpsl5281
@jpsl5281 Жыл бұрын
wba gpt4all
@adeniranm7647
@adeniranm7647 Жыл бұрын
Yeah, but what about AI? 😆
@navigator1819
@navigator1819 Жыл бұрын
Don't put music in the video.
@clem777
@clem777 Жыл бұрын
Hey, there is a recent AI whitepaper where many AI professionals signed... maybe you can cover that. The purpose of the whitepaper is for everyone to fully realise the impacts of AI and its effects on humanity. This may be an interesting follow up video idea. All the best
@fss1704
@fss1704 Жыл бұрын
Not gonna happen
@EdwardsMrJ
@EdwardsMrJ Жыл бұрын
I'm trying to hit the thumbs up, but this useless android version of KZfaq won't let me
@GetToThePointAlready
@GetToThePointAlready Жыл бұрын
Ask ChatGPT if it can fix it for you.
@user-tf9ie2re9x
@user-tf9ie2re9x Жыл бұрын
Is there any way to recover a deleted single audio from android internal storage? Please
@chriscard6544
@chriscard6544 Жыл бұрын
eause recovery, but in linux environnement, you might find other ways with commands
@user-tf9ie2re9x
@user-tf9ie2re9x Жыл бұрын
@@chriscard6544 Thank you, Please, give me email address so that I can communicate with you.
@chriscard6544
@chriscard6544 Жыл бұрын
@@user-tf9ie2re9x you have google to search
@user-tf9ie2re9x
@user-tf9ie2re9x Жыл бұрын
@@chriscard6544 It doesn't work for audio recovery. I tried.
@chriscard6544
@chriscard6544 Жыл бұрын
@@user-tf9ie2re9x sorry
@codecaine
@codecaine Жыл бұрын
😆
@savire.ergheiz
@savire.ergheiz Жыл бұрын
Duh its human being what do you expect 😂 You guys are part of the problem 😂 On the bright side those who falls victim will learn it the hard way of accessing such materials 😁
@parknich081
@parknich081 Жыл бұрын
I tried using chatgpt to code a simple program to detect the current process ID, it ended up having a massive memory leak and blue screened my pc 💀
@trejohnson7677
@trejohnson7677 Жыл бұрын
lel clickbait
@HenrikG1963
@HenrikG1963 Жыл бұрын
Are you sure you are not vomit up in your mouth with the result of it going out of your nose with all these ads in your videos?
@prescientdove
@prescientdove Жыл бұрын
nice, another video that has been made by 100s of other channels. atleast you got another ad off! this channel is basically just your typical ad funnel now.
@RolandHazoto
@RolandHazoto Жыл бұрын
I really wish they would stop calling these things AI, since they aren't AI they are just advanced machine learning. If we keep calling these things AI people are going to be VERY unprepared for actual AI and then we're all going to find out just how many vulnerabilities people have.
@christianjoselopezrosales7275
@christianjoselopezrosales7275 Жыл бұрын
You do realize that a set of instructions in code can be called AI, right? AI contains ML. ML contains Deep Learning, DL contains Neural Networks. NN contains Convoluted (Convolutional?) Neural Networks and so on, my friend.
@tisajokt7676
@tisajokt7676 Жыл бұрын
It is "actual" AI, it's just not significantly generally intelligent at a human level yet. We've had actual AI for quite a while now, because AI is a fairly broad term. Ex. Stockfish is an "actual" AI for playing chess. I do agree, though, that many of the headlines and KZfaqrs probably need to stop watering down the term AGI.
@mfwban6797
@mfwban6797 Жыл бұрын
I respect your videos but I can’t respect your inability to properly sync video with audio
@nordgaren2358
@nordgaren2358 Жыл бұрын
Something must have got messed up in the recording and I didn't catch it in the edit. Sorry. :(
"Please Hack My Computer"
17:50
John Hammond
Рет қаралды 1 МЛН
MFA Can Be Easily Bypassed - Here's How
9:22
Grant Collins
Рет қаралды 86 М.
格斗裁判暴力执法!#fighting #shorts
00:15
武林之巅
Рет қаралды 85 МЛН
Маленькая и средняя фанта
00:56
Multi DO Smile Russian
Рет қаралды 5 МЛН
you need this FREE CyberSecurity tool
32:06
NetworkChuck
Рет қаралды 1,1 МЛН
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 217 М.
The Malware that hacked Linus Tech Tips
10:13
The PC Security Channel
Рет қаралды 1,5 МЛН
Hunt for Hackers with Velociraptor
13:51
John Hammond
Рет қаралды 92 М.
17 AI Tools Every Content Creator Must Know 2024
10:46
EconEase
Рет қаралды 464
Attacking LLM - Prompt Injection
13:23
LiveOverflow
Рет қаралды 365 М.
How Hackers Can Bypass Your Security Defenses
19:31
John Hammond
Рет қаралды 52 М.
Malware Development: Processes, Threads, and Handles
31:29
More Malicious Extensions Found in Chrome Web Store
12:44
Mental Outlaw
Рет қаралды 90 М.
格斗裁判暴力执法!#fighting #shorts
00:15
武林之巅
Рет қаралды 85 МЛН